The truth is that we can't trust INTEL. Their CPU micro-code or ME (Management engine) can and does "phone home" to the internet, grab updates and update the CPU. They don't allow the customer to turn this OFF, which betray's the customer who purchased the CPU. Anyone who can sign the update and intercept the download channel can update your CPU with you having no ability to protect yourself. We can't trust intel. In…
What are some good resources to learn more about the phone-home functionality in their microcode? I've been trying to find more details and have been unable to do so.
Intel Security True Key
111–113 of 113 posts
Re: Intel Security True Key
#112Earlier quoted context omitted.
Providing you have them, I can chop then off and use them. Seriously, use your eye or fingerprint as a password and there is someone ruthless enough to remove them from your body.
Who is this mythical fellow who's not going to give up his password in such a situation anyway? No one's going to protect their accounts at the cost of their finger. Certainly not me. I mean, I agree with not using fingerprints as passwords but not because I want to protect myself from the fingermen.
Placing any security value on human body parts is a stupid idea, whether as a password or as a automated proof of identity.
Re: Intel Security True Key
#113Earlier quoted context omitted.
Who is this mythical fellow who's not going to give up his password in such a situation anyway? No one's going to protect their accounts at the cost of their finger. Certainly not me. I mean, I agree with not using fingerprints as passwords but not because I want to protect myself from the fingermen.
I think you have missed the point. In poorer areas of the world where life is cheaper than cheap, I'm not going to bother negotiating with you, so that you to come to the ATM with me because I need you to place your finger on the scanner. I'm just going to take my machete and remove your whole hand and leave you to bleed out in the dirt. Placing any security value on human body parts is a stupid idea, whether as a pa…
I think it's quite clear we shouldn't use biometrics as passwords but I don't think this is a strong argument.